think i have a spambot how do i get rid of??

Posted on 2011-03-20
Last Modified: 2012-06-21

i have just checked my firewall and its crawing because of all the traffic coming out on port 25 and when i do a netstat -a on my exchange server i am getting the attached, there is a lot of syn going to how do i get rid of or block?
TCP    q102exchange:netbios-ssn  q102exchange.LiteFM.Local:0  LISTENING
  TCP    q102exchange:msexch-routing  q102exchange.LiteFM.Local:2284  ESTABLISHE
  TCP    q102exchange:msexch-routing  q102exchange.LiteFM.Local:2362  ESTABLISHE
  TCP    q102exchange:msexch-routing  q102exchange.LiteFM.Local:2437  ESTABLISHE
  TCP    q102exchange:1068      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:1069      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1090      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1098      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1101      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1105      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1106      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:kpop      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1110      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1111      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1234      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1241      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:1256      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1260      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1266      q102exchange.LiteFM.Local:54922  ESTABLISHED
  TCP    q102exchange:1266      q102exchange.LiteFM.Local:54928  ESTABLISHED
  TCP    q102exchange:1282      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1283      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1284      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1285      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1286      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1287      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1295      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1296      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1299      q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:1300      q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:1313      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:1474      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1567      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1568      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1593      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:2284      q102exchange.LiteFM.Local:msexch-routing  ESTABL
  TCP    q102exchange:2301      q102exchange.LiteFM.Local:0  LISTENING
  TCP    q102exchange:2333      q102dc1.litefm.local:1025  ESTABLISHED
  TCP    q102exchange:2362      q102exchange.LiteFM.Local:msexch-routing  ESTABL
  TCP    q102exchange:2381      q102exchange.LiteFM.Local:0  LISTENING
  TCP    q102exchange:2437      q102exchange.LiteFM.Local:msexch-routing  ESTABL
  TCP    q102exchange:3230      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:ms-wbt-server  q102dc1.litefm.local:1651  ESTABLISHED
  TCP    q102exchange:5698      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:7675      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:8563      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:8952      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:11507     q102dc1.litefm.local:1025  ESTABLISHED
  TCP    q102exchange:19899     q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:30497     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:31617     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:41158     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:41240     q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:43474     q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:53143     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53144     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53145     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53146     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53147     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53148     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53149     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53150     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53177  ESTABLISHED
  TCP    q102exchange:54148     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:54344     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54345     q102exchange.LiteFM.Local:1266  TIME_WAIT
  TCP    q102exchange:54354     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54355     q102exchange.LiteFM.Local:1266  TIME_WAIT
  TCP    q102exchange:54518     q102dc1.litefm.local:epmap  TIME_WAIT
  TCP    q102exchange:54568  ESTABLIS
  TCP    q102exchange:54637  TIME_WAIT
  TCP    q102exchange:54642  TIME_WAIT
  TCP    q102exchange:54820  TIME_WAIT
  TCP    q102exchange:54824  TIME_WAIT
  TCP    q102exchange:54826  TIME_WAIT
  TCP    q102exchange:54827  TIME_WAIT
  TCP    q102exchange:54828  TIME_WAIT
  TCP    q102exchange:54829  TIME_WAIT
  TCP    q102exchange:54830  TIME_WAIT
  TCP    q102exchange:54831  TIME_WAIT
  TCP    q102exchange:54832  TIME_WAIT
  TCP    q102exchange:54834  TIME_WAIT
  TCP    q102exchange:54843  TIME_WAIT
  TCP    q102exchange:54846  TIME_WAIT
  TCP    q102exchange:54847  TIME_WAIT
  TCP    q102exchange:54848  TIME_WAIT
  TCP    q102exchange:54849  TIME_WAIT
  TCP    q102exchange:54850  TIME_WAIT
  TCP    q102exchange:54851  TIME_WAIT
  TCP    q102exchange:54852  TIME_WAIT
  TCP    q102exchange:54853  TIME_WAIT
  TCP    q102exchange:54856  TIME_WAIT
  TCP    q102exchange:54857  TIME_WAIT
  TCP    q102exchange:54858  TIME_WAIT
  TCP    q102exchange:54869  TIME_WAIT
  TCP    q102exchange:54870  TIME_WAIT
  TCP    q102exchange:54871  TIME_WAIT
  TCP    q102exchange:54872  TIME_WAIT
  TCP    q102exchange:54873  TIME_WAIT
  TCP    q102exchange:54874  TIME_WAIT
  TCP    q102exchange:54875  TIME_WAIT
  TCP    q102exchange:54876  TIME_WAIT
  TCP    q102exchange:54877  TIME_WAIT
  TCP    q102exchange:54878  TIME_WAIT
  TCP    q102exchange:54879  TIME_WAIT
  TCP    q102exchange:54882  TIME_WAIT
  TCP    q102exchange:54884  TIME_WAIT
  TCP    q102exchange:54910   SYN_SENT
  TCP    q102exchange:54912   SYN_SENT
  TCP    q102exchange:54913    SYN_SENT
  TCP    q102exchange:54914  SYN_SENT
  TCP    q102exchange:54915   SYN_SENT
  TCP    q102exchange:54917  SYN_SENT
  TCP    q102exchange:54918   SYN_SENT
  TCP    q102exchange:54919   SYN_SENT
  TCP    q102exchange:54921     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54922     q102exchange.LiteFM.Local:1266  ESTABLISHED
  TCP    q102exchange:54927     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54928     q102exchange.LiteFM.Local:1266  ESTABLISHED
  TCP    q102exchange:54935  SYN_SENT
  TCP    q102exchange:54936  SYN_SENT
  TCP    q102exchange:54937   SYN_SENT
  TCP    q102exchange:54938   SYN_SENT
  TCP    q102exchange:54940   SYN_SENT
  TCP    q102exchange:54942   SYN_SENT
  TCP    q102exchange:54944   SYN_SENT
  TCP    q102exchange:54945   SYN_SENT
  TCP    q102exchange:54946   SYN_SENT
  TCP    q102exchange:54947   SYN_SENT
  TCP    q102exchange:54948   SYN_SENT
  TCP    q102exchange:54949  SYN_SENT
  TCP    q102exchange:54950   SYN_SENT
  TCP    q102exchange:54951   SYN_SENT
  TCP    q102exchange:54952  SYN_SENT
  TCP    q102exchange:54953   SYN_SENT
  TCP    q102exchange:54954   SYN_SENT
  TCP    q102exchange:54956  SYN_SENT

  TCP    q102exchange:54957    SYN_SENT
  TCP    q102exchange:54958   SYN_SENT
  TCP    q102exchange:54959   SYN_SENT
  TCP    q102exchange:54960   SYN_SENT
  TCP    q102exchange:54962    SYN_SENT
  TCP    q102exchange:54963    SYN_SENT
  TCP    q102exchange:54964  TIME_WAI
  TCP    q102exchange:54965   SYN_SENT
  TCP    q102exchange:54966   SYN_SENT
  TCP    q102exchange:54967   SYN_SENT
  TCP    q102exchange:54968   SYN_SENT
  TCP    q102exchange:54969   SYN_SENT
  TCP    q102exchange:54970   SYN_SENT
  TCP    q102exchange:54971   SYN_SENT
  TCP    q102exchange:54972   SYN_SENT
  TCP    q102exchange:54973   SYN_SENT
  TCP    q102exchange:54974   SYN_SENT
  TCP    q102exchange:54975  SYN_SENT
  TCP    q102exchange:54976   SYN_SENT
  TCP    q102exchange:54979  SYN_SENT
  TCP    q102exchange:54981   SYN_SENT
  TCP    q102exchange:54982   SYN_SENT
  TCP    q102exchange:54983   SYN_SENT
  TCP    q102exchange:54984    SYN_SENT
  TCP    q102exchange:54985   SYN_SENT
  TCP    q102exchange:54988   SYN_SENT
  TCP    q102exchange:54989   SYN_SENT
  TCP    q102exchange:54990   SYN_SENT
  TCP    q102exchange:54991   SYN_SENT
  TCP    q102exchange:54992   SYN_SENT
  TCP    q102exchange:54993   SYN_SENT
  TCP    q102exchange:54994    SYN_SENT
  TCP    q102exchange:54995   SYN_SENT
  TCP    q102exchange:54996   SYN_SENT
  TCP    q102exchange:54997    SYN_SENT
  TCP    q102exchange:54998   SYN_SENT
  TCP    q102exchange:54999   SYN_SENT
  TCP    q102exchange:55000   SYN_SENT
  TCP    q102exchange:55001  SYN_SENT
  TCP    q102exchange:55002   SYN_SENT
  TCP    q102exchange:55003   SYN_SENT
  TCP    q102exchange:55004   SYN_SENT
  TCP    q102exchange:55005   SYN_SENT
  TCP    q102exchange:55006   SYN_SENT
  TCP    q102exchange:55007   SYN_SENT
  TCP    q102exchange:55008   SYN_SENT
  TCP    q102exchange:55009   SYN_SENT
  TCP    q102exchange:55010   SYN_SENT
  TCP    q102exchange:55011   SYN_SENT
  TCP    q102exchange:55012   SYN_SENT
  TCP    q102exchange:55014    SYN_SENT
  TCP    q102exchange:55015    SYN_SENT
  TCP    q102exchange:55016   SYN_SENT
  TCP    q102exchange:55017   SYN_SENT
  TCP    q102exchange:55018   SYN_SENT
  TCP    q102exchange:55019    SYN_SENT
  TCP    q102exchange:55020  SYN_SENT
  TCP    q102exchange:55021    SYN_SENT
  TCP    q102exchange:55022    SYN_SENT
  TCP    q102exchange:55023   SYN_SENT
  TCP    q102exchange:55024   SYN_SENT
  TCP    q102exchange:55034   SYN_SENT
  TCP    q102exchange:55035   SYN_SENT
  TCP    q102exchange:55036   SYN_SENT
  TCP    q102exchange:55039   SYN_SENT
  TCP    q102exchange:55040   SYN_SENT
  TCP    q102exchange:55041   SYN_SENT
  TCP    q102exchange:55042   SYN_SENT
  TCP    q102exchange:55043   SYN_SENT
  TCP    q102exchange:55044  SYN_SENT
  TCP    q102exchange:55045   SYN_SENT
  TCP    q102exchange:55046   SYN_SENT
  TCP    q102exchange:55047   SYN_SENT
  TCP    q102exchange:55048   SYN_SENT
  TCP    q102exchange:55049   SYN_SENT
  TCP    q102exchange:55050   SYN_SENT
  TCP    q102exchange:55051   SYN_SENT
  TCP    q102exchange:55052   SYN_SENT
  TCP    q102exchange:55053  SYN_SENT
  TCP    q102exchange:55054   SYN_SENT
  TCP    q102exchange:55055   SYN_SENT
  TCP    q102exchange:55056   SYN_SENT
  TCP    q102exchange:55057   SYN_SENT
  TCP    q102exchange:55058   SYN_SENT
  TCP    q102exchange:55060   SYN_SENT
  TCP    q102exchange:55061   SYN_SENT
  TCP    q102exchange:55065  SYN_SENT

  TCP    q102exchange:55066    SYN_SENT
  TCP    q102exchange:55068  ESTABLISHED
  TCP    q102exchange:55069   SYN_SENT
  TCP    q102exchange:55070    SYN_SENT
  TCP    q102exchange:55071   SYN_SENT
  TCP    q102exchange:55072    SYN_SENT
  TCP    q102exchange:55073    SYN_SENT
  TCP    q102exchange:55074   SYN_SENT
  TCP    q102exchange:55075    SYN_SENT
  TCP    q102exchange:55076    SYN_SENT
  TCP    q102exchange:55077    SYN_SENT
  TCP    q102exchange:55078   SYN_SENT
  TCP    q102exchange:55079   SYN_SENT
  TCP    q102exchange:55080   SYN_SENT
  TCP    q102exchange:55081   SYN_SENT
  TCP    q102exchange:55082   SYN_SENT
  TCP    q102exchange:55083   SYN_SENT
  UDP    q102exchange:epmap     *:*
  UDP    q102exchange:snmp      *:*
  UDP    q102exchange:microsoft-ds  *:*
  UDP    q102exchange:isakmp    *:*
  UDP    q102exchange:1026      *:*
  UDP    q102exchange:1027      *:*
  UDP    q102exchange:1050      *:*
  UDP    q102exchange:1087      *:*
  UDP    q102exchange:1267      *:*
  UDP    q102exchange:1709      *:*
  UDP    q102exchange:1710      *:*
  UDP    q102exchange:2306      *:*
  UDP    q102exchange:2340      *:*
  UDP    q102exchange:2354      *:*
  UDP    q102exchange:2883      *:*
  UDP    q102exchange:3456      *:*
  UDP    q102exchange:3457      *:*
  UDP    q102exchange:ipsec-msft  *:*
  UDP    q102exchange:4761      *:*
  UDP    q102exchange:10071     *:*
  UDP    q102exchange:42667     *:*
  UDP    q102exchange:42743     *:*
  UDP    q102exchange:52956     *:*
  UDP    q102exchange:55062     *:*
  UDP    q102exchange:55204     *:*
  UDP    q102exchange:55264     *:*
  UDP    q102exchange:55274     *:*
  UDP    q102exchange:ntp       *:*
  UDP    q102exchange:1028      *:*
  UDP    q102exchange:1047      *:*
  UDP    q102exchange:1051      *:*
  UDP    q102exchange:1053      *:*
  UDP    q102exchange:1077      *:*
  UDP    q102exchange:1088      *:*
  UDP    q102exchange:1237      *:*
  UDP    q102exchange:1312      *:*
  UDP    q102exchange:1475      *:*
  UDP    q102exchange:1497      *:*
  UDP    q102exchange:1592      *:*
  UDP    q102exchange:1595      *:*
  UDP    q102exchange:3456      *:*
  UDP    q102exchange:3457      *:*
  UDP    q102exchange:53483     *:*
  UDP    q102exchange:54147     *:*
  UDP    q102exchange:ntp       *:*
  UDP    q102exchange:netbios-ns  *:*
  UDP    q102exchange:netbios-dgm  *:*

C:\Documents and Settings\webadmin>

Open in new window

Question by:jonathanduane2010
  • 2
LVL 76

Accepted Solution

Alan Hardisty earned 250 total points
ID: 35177034
Are the queues on your Exchange server full of messages your users didn't send?

If so - please have a read of my article:'t-send.html

Author Comment

ID: 35177043
cool, how do i find the sent messages on my exchange server?

Author Comment

ID: 35177052
ok am checking the queues now

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now